Configuration Reference
On this page 5 sections
QSCS reads /etc/qscs/qscs.conf at startup. The Control Panel owns membership, elected roles, origins, persistence policy, and monitoring routing. When the platform publishes a newer configuration revision, the daemon writes a complete replacement and restarts cleanly to activate it.
Minimal host configuration
[QSCS Daemon]
Listen = 4443
Log = true
LogLevel = info
MemoryBudgetPercent = 80
ControlPlane = spooksystems.org
MonitoringHost = monitoring.spooksystems.org
[HTTP Listener]
Port = 8080
Bind = 0.0.0.0[QSCS Daemon]
| Key | Purpose | Operator guidance |
|---|---|---|
Listen | Encrypted peer transport port. | Keep TCP 4443 reachable between cluster peers. |
Log and LogLevel | Journald logging. | Use info normally. Use debug briefly while diagnosing. |
MemoryBudgetPercent | Maximum share of detected host or cgroup memory used by QSCS persistence. | Default is 80. Valid range is 40 to 90. The daemon prunes persisted state when already over budget. |
MeshPeerPull | Allows a cold node to ask a peer for a cache entry before going upstream. | Enable only when every peer supports it. |
ControlPlane | License, configuration, and topology API host. | Normally platform-managed. |
MonitoringHost | Telemetry destination for minute heartbeats, hourly latency probes, and origin health transitions. | Set to the dedicated monitoring endpoint. If empty, telemetry falls back to the control plane. |
Tag, Domain, ConfigRevision | Node identity, cluster tag, and last applied snapshot. | Written by subscription and convergence. Do not edit. |
MasterNodeUuid, TopologyEpoch | Current master identity and fencing generation. | Written by the platform. Do not edit. |
SecondaryMaster | Marks the one platform-selected fallback candidate. | Default false. It is not a general replica toggle. |
[Origins]
Origins are generated from the Control Panel. The master receives the actual backend address. Thin clients use the elected master as their implicit upstream while retaining the same public hostname.
example.com = 127.0.0.1:8084 PersistCache=true HeadlessTimeout=30s| Option | Meaning |
|---|---|
PersistCache=true | Persists eligible anonymous cache entries across restarts. The elected master revalidates and publishes newer cache deltas. Credentialed responses are never covered. |
HeadlessTimeout=30s | Per-origin upstream connect timeout before the normal HEADLESS fallback decision. The panel accepts whole seconds. The daemon also understands millisecond values in local configuration. |
Auth=identity | Requires the QSCS signed identity gate before the origin is reached. |
Proxy=all | Forwards every request to the backend, bypassing cache and delta handling. |
Delta=html, Delta=all, Delta=off | Controls browser delta treatment for the origin. |
[Domain]
203.0.113.10 a1b2c3d4 Master
198.51.100.20 e5f6a7b8Each line is a peer address, TCP port if non-default, and short node tag. Exactly one peer is marked Master. This block is platform-managed.
Applying changes safely
- Make the topology or origin change in the Control Panel.
- Allow the node poll to receive the newer revision. It normally completes within about 20 seconds.
- The daemon writes the complete snapshot and restarts once.
- Verify the applied revision and origin route with
journalctl -u qscs -n 80 --no-pager.
A deliberate qscs subscribe domain <cluster> remains useful after a fresh install, when recovering a node, or when you want an immediate full reconciliation.